Management API Keys
Programmatic credentials for managing your AnyRouter account — keys, presets, BYOK, and credits.
Management keys (ak_…) let you administer your AnyRouter account from scripts, CI pipelines, or other tools — without your dashboard password. They authenticate the management plane: LLM key CRUD, presets, BYOK providers, credits, and your own management keys.
/api/v1/management-keysA management key is authenticated by sending it as a Bearer token (Authorization: Bearer ak_live_…). Management keys are not for LLM inference — to call /api/v1/chat/completions or /api/v1/messages, use an LLM key (sk-ar-…) from /dashboard/keys.
Two kinds of keys
| Key type | Prefix | Purpose | Where to manage |
|---|---|---|---|
| LLM API keys | sk-ar- | Send chat, messages, embeddings, image, and responses requests | /dashboard/keys |
| Management API keys | ak_ | Programmatically manage your account: list/create/revoke LLM keys, configure BYOK, read credits | /dashboard/management-keys |
Request
Create a key from the dashboard (Create key → name it → select scopes → copy the secret shown once), or programmatically from a session-authed request:
| Field | Type | Required | Description |
|---|---|---|---|
name | string | Yes | Human-readable key name. |
description | string | No | Free-text note (e.g. what uses the key). |
scopes | string[] | Yes | The scopes this key grants (see below). |
expires_at | string | No | ISO 8601 expiration timestamp. |
Scopes
Scopes follow the action:resource pattern. write:X implicitly grants read:X. Grant the smallest set a key needs — a leaked read:credits-only key cannot create LLM keys or change BYOK.
| Scope | Grants access to |
|---|---|
read:llm-keys | GET /api/v1/keys, GET /api/v1/key |
write:llm-keys | POST /api/v1/keys, PATCH /api/v1/keys/{hash}, DELETE /api/v1/keys/{hash} |
read:presets | GET /api/v1/presets, GET /api/v1/presets/{slug} |
write:presets | POST /api/v1/presets, PATCH /api/v1/presets/{slug}, DELETE /api/v1/presets/{slug} |
read:byok | GET /api/v1/auth/byok/... |
write:byok | POST/PATCH/DELETE /api/v1/auth/byok/... |
read:credits | GET /api/v1/credits |
read:management-keys | GET /api/v1/management-keys |
write:management-keys | POST /api/v1/management-keys, DELETE /api/v1/management-keys/{id} |
Other routes
| Method & path | Purpose |
|---|---|
GET /api/v1/management-keys | List your management keys. Pass ?include_invalid=true to include revoked/expired keys. |
DELETE /api/v1/management-keys/{id} | Revoke a key immediately (optional revocation_reason body). |
Response
POST /api/v1/management-keys returns the plaintext secret once — store it immediately. Revocation is immediate: the next request with a revoked key returns 401.
Examples
curl -X POST https://anyrouter.dev/api/v1/management-keys \
-H "Content-Type: application/json" \
--cookie "__session=<your-session-cookie>" \
-d '{
"name": "CI deploy bot",
"description": "Used by the GitHub Actions deploy workflow",
"scopes": ["read:credits", "write:llm-keys"],
"expires_at": "2027-01-01T00:00:00Z"
}'
curl https://anyrouter.dev/api/v1/credits \
-H "Authorization: Bearer ak_live_..."
curl https://anyrouter.dev/api/v1/management-keys \
-H "Authorization: Bearer ak_live_..."
curl -X DELETE https://anyrouter.dev/api/v1/management-keys/<key_id> \
-H "Authorization: Bearer ak_live_..." \
-H "Content-Type: application/json" \
-d '{"revocation_reason": "Rotated for quarterly audit"}'
Organization-scoped keys
If your account belongs to an organization, keys you create while the org is active are owned by the org — any member with access can use them and revocation is org-wide. Personal keys are owned by your user and only authenticate you.
Store secrets in a secret manager (1Password, Vault, GitHub Actions Secrets), never in source control. Use the narrowest scope set, set an expires_at where possible, rotate on a schedule, and revoke any key you suspect is compromised.
Errors
| Status | Meaning | Fix |
|---|---|---|
| 401 | Key invalid, revoked, or expired | Create a fresh key from the dashboard. |
| 403 | Key valid but lacks the route's scope | Add the required scope, or use a higher-scoped key. |
Related
- API Keys — the
sk-ar-…LLM keys these credentials manage - Credits API — read balance with
read:credits - Presets API — manage presets with
write:presets - BYOK — configure provider keys with
write:byok